Bug Fix Led to $200M Attack
Whitehat hacker Kankodu had identified the Euler “first deposit bug” in July 2022 and received a $50,000 reward for the discovery.
On this page
The bug fix included the addition of a “donateToReserves” function in Euler’s code, meant to strengthen reserves.
A `donateToReserves` function was added and audited, by the Euler’s team.
However, this modification inadvertently created a more significant vulnerability, which was exploited in the $200 million attack.
“An innocent-looking function ended up compromising the entire protocol. This serves as an expensive lesson to treat even small bug fixes with the same level of importance as major updates,” – says Kankodu.
Fortunately, the Euler team managed to recover most of the drained funds later on.
The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.